A/70/174
IV. Confidence-building measures
16. Confidence-building measures strengthen international peace and security.
They can increase interstate cooperation, transparency, predictability and stability.
In their work to build confidence to ensure a peaceful ICT environment, States
should take into consideration the Guidelines for Confidence-building Measures
adopted by the Disarmament Commission in 1988 and endorsed by consensus by the
General Assembly in resolution 43/78 (H). To enhance trust and cooperation and
reduce the risk of conflict, the Group recommends that States consider the following
voluntary confidence-building measures:
(a) The identification of appropriate points of contact at the policy and
technical levels to address serious ICT incidents and the creation of a directory of
such contacts;
(b) The development of and support for mechanisms and processes for
bilateral, regional, subregional and multilateral consultations, as appropriate, to
enhance inter-State confidence-building and to reduce the risk of misperception,
escalation and conflict that may stem from ICT incidents;
(c) Encouraging, on a voluntary basis, transparency at the bilateral,
subregional, regional and multilateral levels, as appropriate, to increase confidence
and inform future work. This could include the volunta ry sharing of national views
and information on various aspects of national and transnational threats to and in
the use of ICTs; vulnerabilities and identified harmful hidden functions in ICT
products; best practices for ICT security; confidence-building measures developed
in regional and multilateral forums; and national organizations, strategies, policies
and programmes relevant to ICT security;
(d) The voluntary provision by States of their national views of categories of
infrastructure that they consider critical and national efforts to protect them,
including information on national laws and policies for the protection of data and
ICT-enabled infrastructure. States should seek to facilitate cross -border cooperation
to address critical infrastructure vulnerabilities that transcend national borders.
These measures could include:
(i) A repository of national laws and policies for the protection of data and
ICT-enabled infrastructure and the publication of materials deemed
appropriate for distribution on these national laws and policies;
(ii) The development of mechanisms and processes for bilateral, subregional,
regional and multilateral consultations on the protection of ICT -enabled
critical infrastructure;
(iii) The development on a bilateral, subregional, regional and multilateral
basis of technical, legal and diplomatic mechanisms to address ICT -related
requests;
(iv) The adoption of voluntary national arrangements to classify ICT
incidents in terms of the scale and seriousness of the incident, for the purpose
of facilitating the exchange of information on incidents.
17. States should consider additional confidence-building measures that would
strengthen cooperation on a bilateral, subregional, regional and mul tilateral basis.
These could include voluntary agreements by States to:
15-12404
9/17